Prerequisites
Before deployment, confirm that the Apporto instance, infrastructure, network, certificate, and policy prerequisites are complete. Use this page to collect required values, validate platform readiness, and identify any approvals needed before implementation begins.
Apporto currently supports Windows 11 and Windows Server hosts for desktop and application workloads. Note as a Microsoft restriction that when using Windows 11 in any On-Prem configuration, only a Single-Session can be used and launched to each VM.
Linux VM configuration is also supported where applicable.
Instance readiness
After your Apporto license is executed, Apporto provisions your instance using the instance name and URL agreed on during onboarding. Apporto Support then provides the initial control plane administrator login so you can configure the instance, authentication, and desktops.
Confirm the final Apporto instance name and URL.
Identify the initial administrator and any additional local administrators.
Plan identity management integration before production rollout.
Related help articles:
Readiness checklist
Complete this checklist before scheduling installation or production cutover.
Readiness item | Required value or decision | Owner | Status |
|---|---|---|---|
Static IP addresses | Static IP for each Apporto appliance, worker node, gateway, load balancer, and workload VM as applicable. | Network team | Not started |
FQDNs and DNS records | Public or internal FQDNs for the Apporto instance, hyperstream endpoints, gateway, and load balancer. | Network or DNS team | Not started |
SSL certificates | Certificate files, private key, certificate chain, and renewal owner for each endpoint. | Security or PKI team | Not started |
Firewall approval | Approved ingress and egress rules for management, user traffic, DNS, NTP, directory services, RDP, and hypervisor APIs. | Network or security team | Not started |
Selected hypervisor | VMware vSphere, Nutanix Prism, Proxmox Virtual Environment, Hyper-V Server, or physical servers. | Infrastructure team | Not started |
Active Directory | Our Minimum Auth usage is using MS AD. | Customer AD Team | Not started |
MS RDS\TS Cals | Customer responsible for all MS Windows RDS\TS CAL License requirements | Customer License Team | Not started |
Component requirements
Browser compatibility
Apporto runs applications and desktops through an HTML5/WebGL-compatible browser. Apporto validates the latest releases of Google Chrome, Firefox, Safari, and Microsoft Edge.
Google Chrome is recommended for optimal performance.
Apporto components
The following table lists the minimum requirements for the Apporto NextGen on-premises components.
Apporto component | Minimum each | Required |
Apporto manager node | 4 vCPU, 8 GB RAM, 50 GB OS disk, 50 GB data disk | One per cluster |
Apporto worker nodes | 4 vCPU, 12 GB RAM, 50 GB OS disk, 50 GB data disk | At least Three per cluster |
HAProxy | 2 vCPU, 4-6 GB RAM, 50-60 GB disk | 2 Node\VMs. Required if you are not using your own load balancer or content delivery controller |
Workloads and sizing guidelines
For RDS and VDI workload sizing, Apporto recommends using Microsoft’s VM sizing guidance: https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/virtual-machine-recs
Hypervisors
Apporto NextGen can run in a virtualized environment or on physical servers. Virtualized environments are recommended because they support snapshots, automation, and repeatable VM creation.
Physical servers are typically needed only when presenting physical GPU cards without the performance impact or licensing considerations associated with hypervisor passthrough.
Apporto validates the following hypervisors.
Hypervisor | Supported by Apporto |
VMware vSphere | Versions 6.5, 7.x, 8.0 |
Nutanix Prism | Operating system 6.5+ |
Proxmox Virtual Environment | Version 8.0+, 9.0+ |
Hyper-V Server | Server 2025; Gen 1 nodes only |
Plan capacity for VDI/RDS growth and Apporto node cluster expansion as adoption increases. New deployments should also include a backup and disaster recovery plan.
Some features might not be supported on all hypervisor platforms or versions. See the feature documentation for details.
Networking
IP addresses
Assign a static IP address to each deployed component during configuration.
Fully qualified domain names (FQDNs)
Configure FQDNs for the hyperstream endpoints that connect to your load balancer or gateway, including Apporto’s rdp-mgmt-gateway where applicable.
Required ports
Review and approve the required ingress and egress rules before deployment. The exact firewall rules depend on the selected architecture, hypervisor, gateway, directory services, and workload design.
Direction | Component | Source or destination | Port | Protocol | Purpose |
|---|---|---|---|---|---|
Ingress | Apporto appliance | Admin network | 443 | TCP | Cluster node management interface |
Ingress | Apporto appliance | Secure gateway or load balancer | 30443 | TCP | HTTP traffic for Apporto hyperstream and related services |
Ingress | Apporto secure gateway | Admin network | 8443 | TCP | Management interface for the secure gateway |
Ingress | Apporto secure gateway | User network | 443 | TCP | User-initiated traffic to the Apporto hyperstream cluster |
Egress | Apporto appliance and secure gateway | DNS servers | 53 | TCP/UDP | DNS resolution in the local environment |
Egress | Apporto appliance and secure gateway | NTP servers | 123 | UDP | Time synchronization |
Egress | Apporto appliance | Active Directory | 389, 636 | TCP | Directory integration as required by the customer environment |
Egress | Apporto appliance and secure gateway | Public IPs | 443 | TCP | Apporto-required public services, including container registries and management services |
Egress | Apporto appliance | VDI/RDSH servers | 3389 | TCP | RDP access to VDI/RDSH servers used with hyperstream |
Egress | Apporto appliance | Nutanix Prism | 9440 | TCP | Nutanix management API access, required when using Nutanix |
Egress | Apporto appliance | VMware vCenter | 443 | TCP | VMware management API access, required when using VMware |
Certificates
Apporto NextGen requires SSL certificates to secure traffic. If you use your own gateway or load balancer, install the required SSL certificate in the appliance or platform that terminates traffic.
Confirm the certificate common name or SANs, issuing certificate authority, private key availability, certificate chain, expiration date, and renewal owner before installation.
Policy baseline
Apply the Apporto policy baseline to RDS servers and VDI desktops to optimize remote session performance, graphics behavior, security, and profile management. The detailed Group Policy Object settings are maintained on the dedicated GPO page instead of duplicated here.
For the complete policy table, see https://apportoteam.atlassian.net/wiki/spaces/APPORTO/pages/2110816257
At a minimum, confirm that the baseline covers:
Remote session environment and graphics optimization settings.
RDP security layer, encryption, and network-level authentication requirements.
Session limits, Fair Share resource management, and profile management for multi-session deployments.
Additional Microsoft references: